• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-10235
2018-05-22
N/A
7.2 HIGH
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diymodulemembercontrollersadminSetting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diymodulemembermodelsMember_model.php and write this code into the api/ucsso/config.php file.
CVE-2018-10234
2018-05-24
N/A
4.8 MEDIUM
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
CVE-2018-10233
2019-10-06
N/A
8.8 HIGH
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
CVE-2018-10232
2020-07-20
N/A
6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors.
CVE-2018-10231
2018-09-04
N/A
6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVE-2018-10230
2018-05-21
N/A
6.1 MEDIUM
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
CVE-2018-1023
2020-08-24
N/A
7.5 HIGH
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.
CVE-2018-10229
2019-10-03
N/A
4.8 MEDIUM
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
CVE-2018-10228
2021-12-21
N/A
6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
CVE-2018-10227
2018-10-30
N/A
5.4 MEDIUM
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
« Previous 1 … 2,887 2,888 2,889 2,890 2,891 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE